Affects Versions
OpenSSH 4.8p1 and prior
Description of issue
Execution of ~/.ssh/rc for sessions where a command has been forced by the sshd_config ForceCommand directive could allow users with write access to this file could use it to execute arbitrary commands.
Resolution and Availability of Patch
Versions 4.9p1 of OpenSSH fixes this issue and will be included in the April 11 release of the OLEX library. If you have questions about this security warning, or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.
